EP0458210A2 - Procédé et dispositif de transcodage cryptographique de messages - Google Patents
Procédé et dispositif de transcodage cryptographique de messages Download PDFInfo
- Publication number
- EP0458210A2 EP0458210A2 EP91108032A EP91108032A EP0458210A2 EP 0458210 A2 EP0458210 A2 EP 0458210A2 EP 91108032 A EP91108032 A EP 91108032A EP 91108032 A EP91108032 A EP 91108032A EP 0458210 A2 EP0458210 A2 EP 0458210A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- key
- information
- marked
- keys
- subscriber
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1016—Devices or methods for securing the PIN and other transaction-data, e.g. by encryption
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/36—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
- G06Q20/367—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
- H04L9/0841—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
- H04L9/0844—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
- H04L9/16—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/56—Financial cryptography, e.g. electronic payment or e-cash
Definitions
- the invention relates to the field of message conversion and the field of identification of messages, objects, people etc. with the sub-areas "authorization”, “identification” and “authentication”.
- German Patent DE 3827 172 a method is known which solves identification and encryption tasks with a branching network formed randomly from nodes and branches, in which input messages generate output messages associated serially on keying paths; the branching network can be changed as a function of internal and / or external messages.
- the patent provides a very low-cost, space-saving solution for encryption processes and encryption devices with high encryption performance and data rates; this patent does not provide a solution for the authorized, authenticated, encrypted data traffic of process participants. In addition, no cost-optimal solution for the formation of the branch network is given.
- the invention has for its object to provide a method for cost-effective formation of the branch network, and by means of this method to create a timeless, effortless and space-saving device for process-individually encrypted data traffic, which with high encryption performance and data rates to the process participants, among others.
- Claims 16 to 32 characterize preferred configurations of a device which is explained in more detail below as an exemplary embodiment.
- Such a network of branches can be represented in a table by listing all nodes with the respectively assigned parameters.
- FIG. 2 shows the general case of such a list for the branching network according to FIG. 3.
- a branching vector V A 0 was chosen for all nodes, ie each node relates the input message to the order of the branches specified in the list (an "OO" on branch O, a "11" on branch 3 etc. ).
- this sequence can be varied as desired with the branching vector V A ;
- VA 1
- the even-numbered and odd-numbered branches could be interchanged, resulting in a different branching structure.
- each node assigns the key features to the branches, as specified once in the list.
- the characters of an input message select the branches of the branching network serially in nodes and thus select a specific one Conversion path through the network on which the output message is formed depending on the conversion characteristics of the nodes and branches passed through.
- the length of the input message block to be encoded is unlimited, regardless of the number of nodes in the network; however, this number of nodes determines the thickness of the key space and thus the periodicity of the encryption.
- the encryption of an input message can start at any node, which is then binding for the encryption back.
- Data blocks whose last bit to be re-encoded is present at a node with more than 2 branches, as in this example, are separated by the required number of bits e.g. supplemented by OO ..., whereby only one bit of the received output message is to be evaluated accordingly.
- a bit of the output message encrypted according to this method depends on the sum of all previous bits of the input message, ie the change in a single bit of the input message affects all subsequent bits of the output message (avalanche effect).
- the prerequisite for this is that the branches originating from a node have different target nodes.
- This avalanche effect has an effect on all bits of the encrypted message, ie also on the preceding bits, if the output message received in one pass is re-encrypted several times, with the bit sequence being reversed.
- each node of the network has its own individual conversion characteristic, which is characterized by its own conversion key and the characteristics of all subsequent nodes, that is, given by its location in the branch network.
- the key space is determined by the keying characteristics K and the destination addresses A1, which determine the local position of a node relative to the other nodes.
- Each destination address A1 should only appear once and should not name the successor node.
- the i conversion features require i conversion sections (see below).
- the principle is not limited to a destination branch A1 (a destination address A1): N any number of destination branches A1, A2, A3 ... can be implemented per node, even different for each node.
- the chain principle always applies to the first, not saved branch AO.
- the conversion key K and a character of the input message for a selection section then comprise several bits. Such a multiast process thus encodes several bits of the input message at the same time; i.e. has advantages in terms of the conversion rate.
- the storage space for the branching network ie for the key, can be reduced if one of the two influencing variables is predefined and therefore cannot be saved as a key:
- n 2 A nodes with one bit as a conversion key per node require a minimum memory space of only n bits and thus provide a key space of 2 n .
- Memory cells with 8-bit memory capacity thus realize 8 nodes, so that conventional 64-bit keys can be implemented as a branching network in only 8 memory cells.
- the conversion key K can be random information, e.g. Noise generators taken.
- the target addresses A1 can be a random scrambling of the cell addresses Z.
- the method for forming such a network of branches from nodes that are chained together is simple: an address is randomly taken from a set of memory cell addresses 1-n and entered in each of the memory cells 1-n. For a secret generation of such networks in a memory, randomly selected memory cell addresses can thus be "blindly" written into randomly selected memory cells.
- the same branching network effects the conversion for both directions of the conversion by going through the same conversion path for encryption and decryption in the branching network; only the link between the input message and the node information for generating the source information and the destination addresses is different.
- the predetermined functions f K (A1) and f A1 (Z) can be selected uniformly (as above) or differently for each node of the network. They thus offer the possibility of changing the key conversion characteristic and the branching structure uniformly for all nodes or for individual nodes. These changes can take place, for example, after a conversion pass, a conversion section (see below) after each incoming message or depending on external processes.
- the full available key space mentioned above uses input messages, the number of characters of which is sufficient to be able to reach all nodes of the branch network; Incoming messages with a number of characters m ⁇ n use a subset of this key space, depending on the random branching.
- Targeted branching e.g. by the above function for A1
- all the maximum possible nodes can be used for m ⁇ n; however, the share factor in the key space is reduced for the target addresses.
- branching networks realize any key spaces using this method; they only require the minimum storage space of n bits required in principle for a key space 2 n .
- the following explains how a key space implemented using a branch network can be used for messages of limited length at most: Messages with a length of m bits enable 2 m variants and thus 2 m ! (Faculty) possible different scrambling / encryption. For usual message lengths of 64 bits, for example, only a subset of this key volume is implemented in a key space. For messages of just a few bits, however, full use of this key volume is often sought.
- a message of 3 bits for example, enables eg 40320 keys / scrambling that can be realized by encryption using a branch network:
- the input message is encrypted character by character in several runs and for each character position with its own key.
- the character position with its number of possible scrambling determines the thickness of this key assigned to the character.
- the described conversion parameters can be significantly reduced within the intended key space.
- a "network storage" organized according to the method described above, supplemented by means for controlling or changing its Keys or key parameters as well as for controlling the data flow can be used as a key conversion device for a large number of applications.
- Such encryption keys are secure against analytical attacks on the key, since the method is based on inaccessible memory information that cannot be determined externally.
- Mechanical attacks on the key by opening the memory chip and analyzing the information structures can be prevented by suitable storage methods, which lose their memory information during on-chip analysis.
- part of this key information can be known, e.g. standardized, if the other part remains secret.
- the basis of the conversion device is the network memory NM, the n cells of which, as described above, randomly “scrambles" the 1 to n destination addresses A1 and / or conversion key features K and thus form the branching network.
- This network memory NM can be implemented as a read-only memory; possibly "mask programmed”.
- a parameter memory PM also executable as a read-only memory, stores these key parameters for a basic conversion key mode, and loads these basic parameters into the key register KR on request.
- the length of the data block m should not be greater than the number of nodes m of the network, but it should be so large that analytical attacks are hopeless.
- the conversion key characteristic of the device is determined by the branching network and a selection characteristic which codes the pending characters of the input message into selected branches of the branching network.
- This selection characteristic which the key register KR stores as a selection key, enables the key characteristic to be changed without external reloading of the key register, e.g. after each run:
- the selection key S and the input information DIN of the conversion data block thus select the respective branch for the bit to be converted using an EXOR link. Since the selection key is only assigned to the pending character of the input information regardless of the pending node, the same selection key determines the branching of different nodes in different runs. When this selection key is changed, the conversion characteristic changes.
- the key register KR enables such a change in the selection key, among other things. after each incoming message, e.g. by counting (1-addition) the selection key or another specified function with specified parameters. A non-linear change of the selection key would also be possible, e.g. by deriving this key, as well as the conversion characteristics, from a separate conversion device that can be changed linearly by means of a counter.
- a selection key loaded into the key register once at the beginning of the conversion procedure thus forms 2 m conversion characteristics for 2 m conversion data blocks; ie without reloading the key register KR, periodicity only becomes apparent after passing through 2 m of data blocks; until then, each data block encounters a different, individual conversion characteristic.
- An input message that was constantly repeated for the same conversion procedure would therefore only provide a repetition of the converted output message after 2 m of conversions; that is, it provides one-time keys for life.
- This property can be used for pseudorandom generators.
- the m bits of the selection key are interchangeable with the m bits of the input message, provided that the links that depend on them are controlled accordingly in the conversion key. This exchange can be done bit by bit according to the specified function.
- the same encryption path is traversed in the network memory NM; the key direction controls the parameter C by correspondingly different data links in the address selection AS and in the data converter DS.
- This parameter C can be used as an asymmetrical key, i.e. usable only for one encryption direction, encrypted publicly transmitted.
- each bit is dependent on the sum of all preceding bits of the input message, i.e. the change in a single bit of the input message affects all subsequent bits of the converted output message (avalanche effect).
- the feedback register RR converts this linear relationship, which enables cryptanalysis in the case of repeatable procedures, into a non-linear dependency of each output bit on each input bit of the data block.
- the feedback register RR stores the entire re-encrypted data block and, after changing f (R) of the bit sequence, couples it back several times (R) for the purpose of a plurality of re-conversion passes; with the basic parameters listed above e.g. three times, each with the reverse bit sequence.
- the encrypted data block thus obtained is analytically unbreakable.
- a loss of time as a result of these multiple runs can be avoided if the three runs, for example, take place in three network memories NM which are arranged one after the other. All data blocks of a conversion process could pass through the converter without delay with a maximum data rate. The time period to be calculated only once for the collection / buffering in the feedback registers RR would only affect the access time for the output data, but not the data rate.
- All keys determining the decryption by means of a branch network are arbitrary, e.g. random, definable.
- This property enables the completely secret generation and composition of all key information without complex key management and its inaccessible storage, which is also unknown to the key owner, e.g. in extremely miniaturized semiconductor chips.
- Process participants A, B, C etc. can form common keys as a communication basis by putting together their own, encrypted, transmitted partial keys A, B, C.
- keys can be multiplied as required, e.g. individualize hierarchically.
- the authenticity check ensures that two communicating converters A and B have the same key and thus are genuine. If one of the two is undoubtedly genuine, the other one must also be genuine if the test result is positive.
- the check is carried out by comparing the conversion characteristics with any number of random data generated internally with a random generator RD: first A sends encrypted random data to B, receives the same random data decrypted by B and compares it with the original data; then B does the same with A.
- the random generators can e.g. Noise generators or asynchronous high-speed counters.
- Two participants A and B with the same keys can exchange encrypted data with the exclusion of third parties by means of jointly generated, random one-time keys (one time key).
- functions A and B are also technically defined.
- This function is e.g. applicable for cash substitution, which requires a completely internal, self-sufficient, secret random key formation.
- the communication process is initiated by a mutual authenticity check (see above); it ensures that both process participants are real and can communicate with each other.
- A then generates any random data RD internally, stores it in a register KR1 and sends it encrypted to B, which decrypts it and also stores it in register KR1.
- B then generates the corresponding random data, sends it encrypted to A and internally links this random data, e.g. using the EXOR function, with the content of register KR1.
- A decrypts B's random data and uses the same function to link it to the content of its KR1 register.
- Both subscribers thus have a mutually formed random information in the KR1 register, which they load as a key into the key register KR and / or into the network memory NM. Only A and B have this key, third "real" participants cannot "listen” to this common key because they are in the A or B function would have to form the first or the second half of the key with its own random information.
- the common random key formed in this way is the source of a practically unlimited number of one-time keys: both participants A and B change the same way after each conversion of a data block, e.g. your selection key in the key register. This enables one-time keys to be generated for a practically unlimited operating time.
- the key changer differentiates the key data from the user data: encrypted keys contain control information that ensures that the key information only loads the key registers of the key changer internally, but is never delivered externally.
- the decryptor can e.g. a secret, individual, completely anonymous serial no. of the manufacturer, which clearly distinguishes it from all other decoders (e.g. 32 digits long).
- This internal, secret serial number. ID can be loaded as a subscriber key into the key register KR and / or the network memory NM, which gives the transcoder an individual, unmistakable conversion key characteristic.
- the personal assignment of the anonymous converter requires an additional feature.
- a personal characteristic can, for example. any personal identification number devised by the authorized user. (PIN) with any number of digits (e.g. 4 to 16), which can be entered externally when used and internally, e.g. with the secret serial number. ID linked as participant key into Key register KR and / or the network memory NM is loaded. This gives the key changer a distinctive key and user-specific key characteristic.
- This personal assignment therefore does not require any saving of data or other changes to the re-converter, since the PIN is only entered when in use (see authorization). Therefore, the same converter can be personally assigned by several authorized users for different applications.
- the linked assignment of several users is also possible, i.e. only the PIN entered by several users in the correct order reproduce a specific, distinctive conversion characteristic.
- Authorization is the "admission to a sub-process", e.g. the approval of the converter as a "wallet” for payment exchange with authorized “wallets” by a bank or a credit card institute.
- the authorization is preceded by the "authenticity check” and “creation of common random one-time keys” steps.
- the authorization now consists in enabling the subscriber to form a secret process key P which is common to all authorized persons and which identifies all authorized for the sub-process.
- the new subscriber receives the encrypted secret process key P and encrypts it with his individual Participant key I, possibly personalized by one or more PINs, into a participant-related process key AN, which he must remember as an access key to the relevant sub-process.
- this process-specific process key P which is common to all authorized persons, it can be recognized as authorized by all authorized persons by means of an authenticity check (see above) and, based on this process key, can communicate in encrypted form with other authorized persons, possibly with the generation of one-time keys for exclusively two-way communication (see above) ).
- the subscriber-related process key AN can only be used in connection with this PIN. This has the advantage that the user only has to secretly remember a single PIN, for example, for any number of authorizations, and can note the open number of ANs openly; AN has thus become a PAN (P ersonal A utorisier- N umber). This PAN can also be noted in an open, additional memory; eg associatively assigned to the name of the process.
- Public keys are "asymmetrical"; They are accessible to everyone, but only allow one direction of conversion, i.e. they are either transmit keys for encrypting or receive keys for decrypting.
- the keys for the other direction of conversion are only in the possession of the authorized parties, i.e. they are bound to a certain identity. An authorized person can thus unequivocally identify himself as the sender or recipient of a message by possessing the secret send or receive key.
- Unsymmetrical keys for only a given direction of conversion can be formed from symmetrical keys, e.g. linked to control information for the direction of the key to be blocked.
- This control information is parameter C, which is transmitted encrypted together with other parameters.
- Keys are always transmitted encrypted; they are identifiable as a key by means of control information which, when received, only enables the key register and / or the network memory to be loaded internally; external decrypted key information cannot be output.
- Participants with the same conversion characteristics for example, authorized participants (see above) can form "public" keys that are open to the group of participants.
- This key formation takes place using an authorization procedure: The subscriber encrypts a common, public process transmission key P1 or process reception key P2 by means of his subscriber key I into a subscriber-related symmetrical, secret transmission key AN1 or AN2.
- public keys can be kept in the public domain like a telephone book, and can also be added to encrypted messages, for example.
- a participant For communication by means of a public key of another participant, a participant first gains access to the process by means of his own process key AN, ie the shared secret process key P, which then decrypts the public transmit or receive keys AC1 or AC2 and into the key register or loads into the network memory.
- the authorized subscriber in each case loads his individual secret reception or transmission key AN1 or AN2 by entering the common, public transmission key P1 or reception key P2 and re-encoding using his participant key I.
- the "public" of these common transmission or reception keys enables loading the secret key AN1 or AN2 by means of these open keys at the authorized person also from the communication partner.
- the keys AN1 and AN2 remain secret, since they can only be reproduced internally in the encryptor of the authorized person using his subscriber key.
- the authentication is intended to provide proof of the authenticity and completeness of a message.
- a comparison variable is derived from the broadcast text and added to the text, which is uniquely assigned to the broadcast text, ie, identifies its identity beyond doubt.
- This comparison variable must be understandable by the recipient from the text and thus enables proof of the authenticity and completeness of the message by comparison with the supplied authenticator.
- each node or a node group of the branching network is assigned a characteristic bit in a register or memory AM to form basic information for the authenticator, ie this memory is addressed like the branching network with the respectively selected target address NADR.
- this memory AM can be loaded with a defined identification information (eg OOO --- O).
- each called node causes its identification bit to be inverted, so that a text-specific and encryption-specific identification is available as the basis for forming the authenticator in the memory AM at the end of the message.
- This identifier of e.g. n bits for a branching network with n nodes are either added directly or reduced by linking / folding to the text as an authenticator, also encrypted with the transmission key.
- Each recipient who is in possession of the reception key reproduces this authenticator in the course of the decryption, which passes through the same nodes of the branching network, and receives the proof for authenticity and completeness of the message by comparison with the received authenticator.
- the transmission key is secret and tied to a specific identity, the authenticity corresponds to the "electronic signature", since its origin is therefore beyond any doubt and cannot be denied by the originator.
- a "meaningful" signature can then also be transmitted as the authenticator, e.g. Name, address, place of signature, date etc.
- the sender of the message loads the identifier AM into the key register KR and encrypts this "meaningful" signature with this sender and text-specific key and adds it to the text as an authenticator as above.
- the recipient also uses the text to form the key to be loaded into the key register KR for decrypting the signature. This solution enables the signature to always appear the same.
- Plain texts can also be electronically signed and authenticated using the encryption described, in that the sender uses the encryption procedure to form the authenticity of the plain text and sends this to the recipient in encrypted form as an associated signature; if applicable, together with its associated public key.
- the electronic acknowledgment of receipt can also be authenticated:
- the recipient uses the identifier AM formed for the received text or passes it on with the confirming text, forms an authenticator with it as described above via text and confirmation and sends it encrypted with its own secret transmission key to the communication partner as a receipt; if applicable, together with its associated public key.
- the originator cannot deny this receipt.
- a meaningful signature can also be used here as the authenticator.
- the method enables multifunctional, inexpensive conversion devices which, as a microchip with an extremely small chip area, offer all cryptographic functions with a practically unlimited number of keys; this at extremely high data rates, since this method does not use complex arithmetic operations but memory operations.
- these conversion devices can be used as random generators with practically unlimited periodicity; they enable unbreakable encryption with one-time keys with unlimited, i.e. lifelong key supply.
- the conversion device with a balancing and storage means for cash amounts to an authorized “electronic wallet” for "authentifiable money” which can exchange cash amounts with fully authorized and completely encrypted with equally authorized wallets.
- the designed process can also be used as a software / firmware solution.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Finance (AREA)
- Signal Processing (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- Theoretical Computer Science (AREA)
- Strategic Management (AREA)
- Storage Device Security (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
- Compression, Expansion, Code Conversion, And Decoders (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| AT91108032T ATE95654T1 (de) | 1990-05-22 | 1991-05-17 | Verfahren und einrichtung zur nachrichtenumschluesselung. |
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE4016491 | 1990-05-22 | ||
| DE4016491 | 1990-05-22 | ||
| DE4114777A DE4114777A1 (de) | 1990-05-22 | 1991-05-07 | Verfahren und einrichtung zur nachrichtenumschluesselung |
| DE4114777 | 1991-05-07 |
Publications (3)
| Publication Number | Publication Date |
|---|---|
| EP0458210A2 true EP0458210A2 (fr) | 1991-11-27 |
| EP0458210A3 EP0458210A3 (en) | 1992-01-02 |
| EP0458210B1 EP0458210B1 (fr) | 1993-10-06 |
Family
ID=25893454
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP91108032A Expired - Lifetime EP0458210B1 (fr) | 1990-05-22 | 1991-05-17 | Procédé et dispositif de transcodage cryptographique de messages |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US5224164A (fr) |
| EP (1) | EP0458210B1 (fr) |
| JP (1) | JP3140482B2 (fr) |
| DE (1) | DE4114777A1 (fr) |
| ES (1) | ES2047359T3 (fr) |
Families Citing this family (51)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7028187B1 (en) * | 1991-11-15 | 2006-04-11 | Citibank, N.A. | Electronic transaction apparatus for electronic commerce |
| DE4142964C2 (de) * | 1991-12-24 | 2003-05-08 | Gao Ges Automation Org | Datenaustauschsystem mit Überprüfung der Vorrichtung auf Authentisierungsstatus |
| US5544322A (en) * | 1994-05-09 | 1996-08-06 | International Business Machines Corporation | System and method for policy-based inter-realm authentication within a distributed processing system |
| US5473692A (en) * | 1994-09-07 | 1995-12-05 | Intel Corporation | Roving software license for a hardware agent |
| US6950810B2 (en) * | 1994-11-28 | 2005-09-27 | Indivos Corporation | Tokenless biometric electronic financial transactions via a third party identicator |
| US7152045B2 (en) | 1994-11-28 | 2006-12-19 | Indivos Corporation | Tokenless identification system for authorization of electronic transactions and electronic transmissions |
| US6269348B1 (en) | 1994-11-28 | 2001-07-31 | Veristar Corporation | Tokenless biometric electronic debit and credit transactions |
| US7882032B1 (en) | 1994-11-28 | 2011-02-01 | Open Invention Network, Llc | System and method for tokenless biometric authorization of electronic communications |
| US5870723A (en) * | 1994-11-28 | 1999-02-09 | Pare, Jr.; David Ferrin | Tokenless biometric transaction authorization method and system |
| US7613659B1 (en) | 1994-11-28 | 2009-11-03 | Yt Acquisition Corporation | System and method for processing tokenless biometric electronic transmissions using an electronic rule module clearinghouse |
| US7631193B1 (en) | 1994-11-28 | 2009-12-08 | Yt Acquisition Corporation | Tokenless identification system for authorization of electronic transactions and electronic transmissions |
| US6397198B1 (en) | 1994-11-28 | 2002-05-28 | Indivos Corporation | Tokenless biometric electronic transactions using an audio signature to identify the transaction processor |
| US20040128249A1 (en) * | 1994-11-28 | 2004-07-01 | Indivos Corporation, A Delaware Corporation | System and method for tokenless biometric electronic scrip |
| US6154879A (en) * | 1994-11-28 | 2000-11-28 | Smarttouch, Inc. | Tokenless biometric ATM access system |
| US6230148B1 (en) | 1994-11-28 | 2001-05-08 | Veristar Corporation | Tokenless biometric electric check transaction |
| US7248719B2 (en) * | 1994-11-28 | 2007-07-24 | Indivos Corporation | Tokenless electronic transaction system |
| US5870473A (en) * | 1995-12-14 | 1999-02-09 | Cybercash, Inc. | Electronic transfer system and method |
| GB9601924D0 (en) * | 1996-01-31 | 1996-04-03 | Certicom Corp | Transaction verification protocol for smart cards |
| US8229844B2 (en) | 1996-06-05 | 2012-07-24 | Fraud Control Systems.Com Corporation | Method of billing a purchase made over a computer network |
| US20030195848A1 (en) | 1996-06-05 | 2003-10-16 | David Felger | Method of billing a purchase made over a computer network |
| US7555458B1 (en) | 1996-06-05 | 2009-06-30 | Fraud Control System.Com Corporation | Method of billing a purchase made over a computer network |
| JP3867251B2 (ja) * | 1996-09-13 | 2007-01-10 | テミツク セミコンダクター ゲゼルシヤフト ミツト ベシユレンクテル ハフツング | 無線周波数識別システムにおいてデータを伝送する方法 |
| US6980670B1 (en) * | 1998-02-09 | 2005-12-27 | Indivos Corporation | Biometric tokenless electronic rewards system and method |
| US6356935B1 (en) | 1998-08-14 | 2002-03-12 | Xircom Wireless, Inc. | Apparatus and method for an authenticated electronic userid |
| US6085321A (en) | 1998-08-14 | 2000-07-04 | Omnipoint Corporation | Unique digital signature |
| US6615348B1 (en) | 1999-04-16 | 2003-09-02 | Intel Corporation | Method and apparatus for an adapted digital signature |
| WO2001019015A2 (fr) * | 1999-09-09 | 2001-03-15 | Tri D Store Ip, Llc | Application de modele automatise pour la protection d'informations |
| US20040186996A1 (en) * | 2000-03-29 | 2004-09-23 | Gibbs Benjamin K. | Unique digital signature |
| AU2001266628A1 (en) | 2000-05-31 | 2001-12-11 | Indivos Corporation | Biometric financial transaction system and method |
| US9165323B1 (en) | 2000-05-31 | 2015-10-20 | Open Innovation Network, LLC | Biometric transaction system and method |
| US7155011B2 (en) * | 2001-03-13 | 2006-12-26 | Victor Company Of Japan, Limited | Encryption method, decryption method, and recording and reproducing apparatus |
| JP2003134106A (ja) * | 2001-10-22 | 2003-05-09 | Victor Co Of Japan Ltd | 暗号化方法、復号化方法及び装置、並びに情報記録媒体 |
| WO2005086802A2 (fr) | 2004-03-08 | 2005-09-22 | Proxense, Llc | Systeme de compte lie utilisant une cle numerique personnelle |
| RU2007127725A (ru) | 2004-12-20 | 2009-01-27 | ПРОКСЕНС, ЭлЭлСи (US) | Аутентификация по биометрическому ключу персональных данных (pdk) |
| JP4662799B2 (ja) * | 2005-03-28 | 2011-03-30 | 昭和情報機器株式会社 | 暗号化通信システム |
| US8874477B2 (en) | 2005-10-04 | 2014-10-28 | Steven Mark Hoffberg | Multifactorial optimization system and method |
| US8433919B2 (en) | 2005-11-30 | 2013-04-30 | Proxense, Llc | Two-level authentication for secure transactions |
| US8340672B2 (en) | 2006-01-06 | 2012-12-25 | Proxense, Llc | Wireless network synchronization of cells and client devices on a network |
| US11206664B2 (en) | 2006-01-06 | 2021-12-21 | Proxense, Llc | Wireless network synchronization of cells and client devices on a network |
| US9269221B2 (en) | 2006-11-13 | 2016-02-23 | John J. Gobbi | Configuration of interfaces for a location detection system and application |
| WO2009062194A1 (fr) | 2007-11-09 | 2009-05-14 | Proxense, Llc | Capteur de proximité de support de services d'applications multiples |
| US8171528B1 (en) | 2007-12-06 | 2012-05-01 | Proxense, Llc | Hybrid device having a personal digital key and receiver-decoder circuit and methods of use |
| US9251332B2 (en) | 2007-12-19 | 2016-02-02 | Proxense, Llc | Security system and method for controlling access to computing resources |
| WO2009102979A2 (fr) | 2008-02-14 | 2009-08-20 | Proxense, Llc | Système de gestion de soins de santé de proximité équipé d’un accès automatique aux informations privées |
| US11120449B2 (en) | 2008-04-08 | 2021-09-14 | Proxense, Llc | Automated service-based order processing |
| CN102625302B (zh) * | 2008-06-23 | 2016-03-30 | 华为技术有限公司 | 密钥衍生方法、设备及系统 |
| US20100242104A1 (en) * | 2009-03-23 | 2010-09-23 | Wankmueller John R | Methods and systems for secure authentication |
| US9418205B2 (en) | 2010-03-15 | 2016-08-16 | Proxense, Llc | Proximity-based system for automatic application or data access and item tracking |
| US9322974B1 (en) | 2010-07-15 | 2016-04-26 | Proxense, Llc. | Proximity-based system for object tracking |
| US9265450B1 (en) | 2011-02-21 | 2016-02-23 | Proxense, Llc | Proximity-based system for object tracking and automatic application initialization |
| US9405898B2 (en) | 2013-05-10 | 2016-08-02 | Proxense, Llc | Secure element as a digital pocket |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE2639806C2 (de) * | 1976-09-03 | 1978-06-22 | Siemens Ag, 1000 Berlin Und 8000 Muenchen | Verfahren und Einrichtung zum Verschlüsseln oder Entschlüsseln von Datenblöcken in binärer Darstellung |
| US4458109A (en) * | 1982-02-05 | 1984-07-03 | Siemens Corporation | Method and apparatus providing registered mail features in an electronic communication system |
| US4460992A (en) * | 1982-11-04 | 1984-07-17 | The United States Of America As Represented By The Secretary Of The Army | Orthogonal CDMA system utilizing direct sequence pseudo noise codes |
| DE3827172A1 (de) * | 1987-08-13 | 1989-03-16 | Peter Elsner | Einrichtung zur identifizierung von nachrichten |
| FR2624992B1 (fr) * | 1987-12-21 | 1990-04-06 | Comp Generale Electricite | Generateur de signal temporel periodique genre fractal |
| US4919545A (en) * | 1988-12-22 | 1990-04-24 | Gte Laboratories Incorporated | Distributed security procedure for intelligent networks |
-
1991
- 1991-05-07 DE DE4114777A patent/DE4114777A1/de active Granted
- 1991-05-17 ES ES91108032T patent/ES2047359T3/es not_active Expired - Lifetime
- 1991-05-17 EP EP91108032A patent/EP0458210B1/fr not_active Expired - Lifetime
- 1991-05-20 US US07/703,157 patent/US5224164A/en not_active Expired - Lifetime
- 1991-05-22 JP JP03117621A patent/JP3140482B2/ja not_active Expired - Lifetime
Also Published As
| Publication number | Publication date |
|---|---|
| JP3140482B2 (ja) | 2001-03-05 |
| US5224164A (en) | 1993-06-29 |
| JPH0614017A (ja) | 1994-01-21 |
| EP0458210A3 (en) | 1992-01-02 |
| DE4114777A1 (de) | 1992-02-06 |
| ES2047359T3 (es) | 1994-02-16 |
| DE4114777C2 (fr) | 1993-04-29 |
| EP0458210B1 (fr) | 1993-10-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP0458210B1 (fr) | Procédé et dispositif de transcodage cryptographique de messages | |
| DE69831982T2 (de) | Kryptographisches vermittlungsverfahren und gerät | |
| DE69416809T2 (de) | Verbesserungen der Sicherheit in Datenverarbeitungssystemen | |
| DE69222090T2 (de) | Einrichtung und Verfahren zum blockweisen Verschlüsseln von Daten | |
| DE69632707T2 (de) | Verschlüsselungseinrichtung mit doppelter vorwärtsgeregelter Hash-Funktion | |
| DE60315700T2 (de) | Verfahren zum erzeugen einer stromverschlüsselung mit mehreren schlüsseln | |
| EP0820670A1 (fr) | Procede pour l'echange cryptographique de cles assiste par ordinateur entre un ordinateur utilisateur (u) et un ordinateur reseau (n) | |
| WO2009103364A1 (fr) | Procédé de cryptage aléatoire et de décryptage aléatoire de données relatifs à des accès et des communications | |
| EP1298834A1 (fr) | Procédé et dispositif de chiffrement et de déchiffrement des données | |
| DE60116195T2 (de) | Vorrichtung und Verfahren zur Verschleierung von Eingangsparametern | |
| EP2647157A1 (fr) | Procédé et dispositif permettant d'effectuer un chiffrement de flux symétrique de données | |
| EP4099611B1 (fr) | Génération de la clé quantique sûre dans un réseau | |
| DE69737806T2 (de) | Datenverschlüsselungsverfahren | |
| DE102008042406B4 (de) | Verfahren zum sicheren Austausch von Daten | |
| EP1573955B1 (fr) | Procede de chiffrement | |
| EP3734486B1 (fr) | Procédé exécuté par ordinateur permettant de remplacer une chaîne de données | |
| EP2288073B1 (fr) | Dispositif destiné au codage de données | |
| DE10128300A1 (de) | Authentisierungsverfahren | |
| DE102004001490A1 (de) | Verfahren zur Authentifizierung einer Nachricht | |
| WO2007099026A1 (fr) | Procédé et dispositif d'authentification d'une clé publique | |
| DE102007023206B4 (de) | Verfahren und Einrichtung zur sicheren Erzeugung und Verwaltung von Schlüsseln und deren Nutzung in Netzwerken zur sicheren Übertragung von Daten | |
| DE10223217A1 (de) | Verfahren und Anordnung zur Verschlüsselung bzw. Entschlüsselung von Datenpaketen in drahtlosen Netzwerken | |
| DE19807020A1 (de) | Mittel zur sicheren Chiffrierung von Daten | |
| DE4420967A1 (de) | Entschlüsselungseinrichtung von digitalen Informationen und Verfahren zur Durchführung der Ver- und Entschlüsselung derselben | |
| DE19942082A1 (de) | Verfahren zur Sicherung und Beglaubigung elektronisch übermittelter Texte |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| PUAL | Search report despatched |
Free format text: ORIGINAL CODE: 0009013 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT CH ES FR GB IT LI NL SE |
|
| AK | Designated contracting states |
Kind code of ref document: A3 Designated state(s): AT CH ES FR GB IT LI NL SE |
|
| 17P | Request for examination filed |
Effective date: 19920604 |
|
| 17Q | First examination report despatched |
Effective date: 19920731 |
|
| GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
| AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): AT CH ES FR GB IT LI NL SE |
|
| REF | Corresponds to: |
Ref document number: 95654 Country of ref document: AT Date of ref document: 19931015 Kind code of ref document: T |
|
| ITF | It: translation for a ep patent filed | ||
| ET | Fr: translation filed | ||
| REG | Reference to a national code |
Ref country code: ES Ref legal event code: FG2A Ref document number: 2047359 Country of ref document: ES Kind code of ref document: T3 |
|
| GBT | Gb: translation of ep patent filed (gb section 77(6)(a)/1977) |
Effective date: 19940209 |
|
| PLBE | No opposition filed within time limit |
Free format text: ORIGINAL CODE: 0009261 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT |
|
| 26N | No opposition filed | ||
| EAL | Se: european patent in force in sweden |
Ref document number: 91108032.3 |
|
| REG | Reference to a national code |
Ref country code: GB Ref legal event code: IF02 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: IT Payment date: 20060531 Year of fee payment: 16 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IT Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20070517 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: FR Payment date: 20100525 Year of fee payment: 20 Ref country code: ES Payment date: 20100514 Year of fee payment: 20 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: NL Payment date: 20100527 Year of fee payment: 20 Ref country code: AT Payment date: 20100514 Year of fee payment: 20 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: CH Payment date: 20100517 Year of fee payment: 20 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: GB Payment date: 20100514 Year of fee payment: 20 Ref country code: SE Payment date: 20100514 Year of fee payment: 20 |
|
| REG | Reference to a national code |
Ref country code: NL Ref legal event code: V4 Effective date: 20110517 |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: PL |
|
| REG | Reference to a national code |
Ref country code: GB Ref legal event code: PE20 Expiry date: 20110516 |
|
| REG | Reference to a national code |
Ref country code: SE Ref legal event code: EUG |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: NL Free format text: LAPSE BECAUSE OF EXPIRATION OF PROTECTION Effective date: 20110517 Ref country code: GB Free format text: LAPSE BECAUSE OF EXPIRATION OF PROTECTION Effective date: 20110516 |
|
| REG | Reference to a national code |
Ref country code: ES Ref legal event code: FD2A Effective date: 20130725 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: ES Free format text: LAPSE BECAUSE OF EXPIRATION OF PROTECTION Effective date: 20110518 |